Transcription of OpenScape Business V2 - Unify
1 OpenScape Business V2 Tutorial System Device@Home Configuration Version Table of Contents 1. Configuration Overview 5 Network Scenario Description: 5 Configuration Steps 5 Overview OpenScape Business Configuration 6 Overview Company Internet Router Configuration 6 Overview System Device@Home Configuration 6 Technical boundaries and limitations 6 Internet access of OpenScape Business 6 NAT configuration within Company and Home Router 6 myPortal to go VoIP client: 7 OpenScape DeskPhone CP 400/600: 7 Secured Connections to System Device @Home 7 Desksharing Support 7 Capacities 7 2. OpenScape Business configuration 8 Supported Internet Access Scenarios for System Device@Home 8 OpenScape Business behind access router connected to LAN2 interface 8 Configuring a System Client to be used from Internet 8 Configuring the number of simultaneous internet calls 9 Configuring STUN 9 Port configuration within OpenScape Business 9 Signalling Ports 9 Voice Payload Ports 10 Configuring SW Deployment 10 Configuring SPE (optional) 10 SPE Enabling for the system 10 SPE enabling for Stations 11 SPE Certificates 11 3.
2 Company Internet Router Configuration 14 Port forwarding / firewall 14 Internet access with dynamic IP Address (DynDNS) 15 NAT type 15 4. System Device configuration 16 System Device Configuration 16 myPortal to go VoIP Client configuration 16 5. Home Internet Router 18 6. Security considerations 19 7. Troubleshooting 20 8. Abbreviations 21 Table of History Date Version Changes 2016-02-25 Initial Creation for OpenScape Business V2R1 2016-03-24 Minor enhancements and functional boundary regarding WAN interface added 2016-06-16 Enhancements for V2R2 2017-06-29 Enhancements for V2R3 2019-03-06 Enhancements for V2R6 Chapter added for Signalling and Payload Encryption (SPE) 2019-07-24 Enhancements for V2R7 myPortal @work remote usage via device@home This document describes the required configuration steps for the configuration of the feature Device@Home for System Devices.
3 It also provides useful information regarding supported scenarios, known limitations and security considerations. This description refers to OpenScape Business V2R7. Within the following the term System Device is used in general for the following system clients, which support the HFA protocol: OpenStage, OpenScape DeskPhone IP and OpenScape DeskPhone CP phones as well as the integrated VoIP clients for myPortal @work (WebRTC) and myPortal to go. 1. Configuration Overview The feature Device@Home offers registration and operation of System Devices, which are connected over the Internet as internal devices of OpenScape Business . For all examples within the document, the following basic network scenario is used..Company NetworkITSPD evice@HomeCompanyinternet routerHome RouterHome NetworkPublicInternetCOPublic IP :- IP :- Figure 1 Typical network environment OpenScape Business is located within a company LAN, which is connected to the Internet via the Company Internet Router.
4 This router is accessible from the Internet either via public IP Address or via DNS name The System Device@Home is connected to the LAN within a Home Network, which is connected to the Internet via a Home Internet Router. The Home Router is accessible from the Internet with the public Internet Address Within the Internet a STUN (Session traversal Utilities for NAT) Server for public IP address discovery and an ITSP for Internet Telephone in general are available. To connect the System Device@Home to OpenScape Business the following components need to be configured accordingly: OpenScape Business system within the company Company Internet Router System Devices @Home myPortal to go client (optional). myPortal @work (optional) Overview OpenScape Business Configuration In OpenScape Business the following configuration steps are required: Activate STUN support, if not already done for an ITSP, which is connected to OpenScape Business .
5 Configure the number of simultaneous Internet calls . This value is implicitly set when the parameter upstream up to (Kbps) is set to a useful value in the basic installation wizard. Configure System Client as externally connected client o Assign an IP user license. (This is also required if the myPortal to go VoIP option is used). o Enable Authentication and configure STRONG passwords for the System Device@Home, which is connected via Internet. o Allow System Client registration from external ( over the Internet) individually for each System Client by activating the integrated SBC function for that System Client. Enable SW Deployment for @home devices Optional: Enable signalling (and payload) encryption (SPE) for the System Device@home (only if required). Overview Company Internet Router Configuration As the System Device@Home must reach the OpenScape Business system from the Internet and vice versa.
6 The following configuration steps have to be done for the Company Internet Router: Configuration of a UDP port forwarding (see 3) for the RTP protocol port range. Configuration of a TCP port forwarding for the HFA protocol (when using System Devices). Configuration of a TCP port forwarding rule for the DLI service Optional: Configuration of a TCP port forwarding rule for HTTPS (only when using myPortal to go VoIP @Home, myPortal @work (remote) or DeskPhone CP 400/600 Note: If the company Internet router restricts outbound IP traffic, it may be necessary to explicitly open the ports also for outgoing IP traffic. The normal SW-Update procedure of the DLI for an internally connected device cannot be used for System Device (HFA)@Home as the DLI cannot determine the IP address of device which resides in a LAN environments using NAT in the Internet Router.)
7 Therefore the DLI SW-Update procedure uses an additional HTTPS connection via port 8804 (default setting) in combination with the DLI port 18443 (default setting) to determine SW version of the Device@Home and to perform the SW-Update. Overview System Device@Home Configuration Within the System Device@Home, following configuration steps have to be fulfilled: Configuration of the gateway IP address: Enter the public IP address (if fix) or public domain name of the OpenScape Business Configuration of the HFA password Configuration of DLS: Internet access of OpenScape Business Device@Home is tested and released for connection to the LAN2 interface of OpenScape Business . The WAN (LAN1) interface is not supported ITSP trunks and System Device@Home have to be connected to the same LAN interface of OpenScape Business .
8 Using different LAN interfaces, ITSP connected to the LAN 1 (WAN) and Device@Home connected via Internet to LAN 2, is not supported. NAT configuration within Company and Home Router Routers with NAT type Symmetric NAT are not compatible to the Device@Home solution. If the NAT behaviour is configurable in the router, it needs to be changed accordingly if possible. Note: The NAT type detection of the OpenScape Business (see Assistant) may falsely detect the NAT type of the Company router as Symmetric NAT , if outbound IP traffic is restricted in the Company Internet router. myPortal to go VoIP client: The VoIP client within the myPortal to go App requires direct HTTPS access to TCP/8802 port within OpenScape Business . myPortal to go VoIP supports only codec. myPortal @work VoIP Client: The VoIP client within the myPortal @work Application requires direct HTTPS access to TCP/8802 port within OpenScape Business .
9 MyPortal @work client supports Opus audio codec between two myPortal @work stations and codec to other stations. OpenScape DeskPhone CP 400/600: The OpenScape DeskPhone CP 400/600 requires direct HTTPS access to TCP/8802 port within OpenScape Business , if UC server access is configured. Secured Connections to System Device @Home Signaling: For secured connections the TLS protocol is used for encryption of the signaling information. TLS version is used per default. A fallback to TLS is possible in V2R6, if the device does not support TLS TLS is not supported at WAN interface. Payload: Payload encryption using SRTP and SDES is not supported for System Device Desksharing Support The feature System Device@Home, incl. myPortal to go VoIP and myPortal @work client, is not released in combination with Deskshare mobility (relocate), nevertheless up from V2R7 myPortal @work can be used in different user scenarios, for in the office or being at home, by using the new profile selection on login screen.
10 Capacities Open Scape Business uses a so called RTP proxy for all VoIP connection via Internet. The RTP Proxy offers a shared pool with a limited amount of channels which are assigned to the Internet connections as follows: 1 RTP proxy channel per ITSP call 1 RTP proxy channel per Circuit call 1 RTP proxy channel per System Device @Home in a call 1 RTP proxy channel per SIP Device @Home in a call 1 RTP proxy channel per myPortal to go VoIP @Home in a call Within the different OpenScape Business models following resources are available: System variant RTP proxy channels OpenScape Business X1/X3/X5/X8 with or without Booster card/server 60 OpenScape Business S 180 2. OpenScape Business configuration In general there are different scenarios to connect OpenScape Business system to the internet.